CVE-2018-12684: Infoleak
Out-of-bounds Read in the sendssifile function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-12684?
CVE-2018-12684 is a vulnerability in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 that allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
How severe is CVE-2018-12684?
CVE-2018-12684 has a severity level of 7.1 (high).
What is the affected software of CVE-2018-12684?
The affected software of CVE-2018-12684 is CivetWeb through version 1.10.
How can CVE-2018-12684 be fixed?
To fix CVE-2018-12684, it is recommended to update CivetWeb to version 1.10 or apply the necessary patches provided by the vendor.
Where can I find more information about CVE-2018-12684?
You can find more information about CVE-2018-12684 on the following references: [GitHub - CivetWeb Commit](https://github.com/civetweb/civetweb/commit/8fd069f6dedb064339f1091069ac96f3f8bdb552), [GitHub - CivetWeb Issue](https://github.com/civetweb/civetweb/issues/633)